CVE-2020-36326
Summary
| CVE | CVE-2020-36326 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-28 03:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation. |
Risk And Classification
Problem Types: CWE-502
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 34 Update: php-phpmailer6-6.4.1-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: php-phpmailer6-6.4.1-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Proposed fix for #2069 · PHPMailer/PHPMailer@e2e07a3 · GitHub | MISC | github.com | |
| [SECURITY] Fedora 33 Update: php-phpmailer6-6.4.1-1.fc33 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 33 Update: php-phpmailer6-6.4.1-1.fc33 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178741 Debian Security Update for wordpress (DLA 2731-1)
- 281210 Fedora Security Update for php (FEDORA-2021-b21bbfa198)
- 281211 Fedora Security Update for php (FEDORA-2021-ecf4fed550)
- 690089 Free Berkeley Software Distribution (FreeBSD) Security Update for mantis (9b1699ff-d84c-11eb-92d6-1b6ff3dfe4d3)
- 730078 WordPress Prior to 5.7.2 Multiple Vulnerabilities